[原文]EFTP 220.127.116.117 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
EFTP LS Command Traversal Authentication Information Disclosure
Remote / Network Access
Loss of Confidentiality,
Loss of Integrity
EFTP contains a flaw that allows a remote attacker traverse the file system using a directory traversal style attack (../../). If such a request is made to a network share, it will force the system to send out authentication credentials to the network. Used in conjunction with a third party sniffing tool, the username/password can be obtained.
Upgrade to version 3.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.